Tagged “pip”
CVEs tagged pip, newest first.
4637 CVEsRSS
CVE-2026-34450MediumClaude SDK for Python has Insecure Default File Permissions in Local Filesystem Memory Tool
Claude SDK for Python has Insecure Default File Permissions in Local Filesystem Memory Tool
CVE-2026-34515MediumAIOHTTP affected by UNC SSRF/NTLMv2 Credential Theft/Local File Read in static resource handler on Windows
AIOHTTP affected by UNC SSRF/NTLMv2 Credential Theft/Local File Read in static resource handler on Windows
CVE-2026-34519LowAIOHTTP has HTTP response splitting via \r in reason phrase
AIOHTTP has HTTP response splitting via \r in reason phrase
CVE-2026-34516High· 7.5AIOHTTP has a Multipart Header Size Bypass
AIOHTTP has a Multipart Header Size Bypass
CVE-2026-34730Medium· 5.5Copier `_external_data` allows path traversal and absolute-path local file read without unsafe mode
Copier `_external_data` allows path traversal and absolute-path local file read without unsafe mode
CVE-2026-34513LowAIOHTTP Affected by Denial of Service (DoS) via Unbounded DNS Cache in TCPConnector
AIOHTTP Affected by Denial of Service (DoS) via Unbounded DNS Cache in TCPConnector
CVE-2026-34446Medium· 4.7ONNX: Arbitrary File Read via ExternalData Hardlink Bypass in ONNX load
ONNX: Arbitrary File Read via ExternalData Hardlink Bypass in ONNX load
CVE-2026-34525MediumAIOHTTP accepts duplicate Host headers
AIOHTTP accepts duplicate Host headers
CVE-2026-34518Medium· 5.3AIOHTTP leaks Cookie and Proxy-Authorization headers on cross-origin redirect
AIOHTTP leaks Cookie and Proxy-Authorization headers on cross-origin redirect
CVE-2026-34939Medium· 6.5PraisonAI Has ReDoS via Unvalidated User-Controlled Regex in MCPToolIndex.search_tools()
PraisonAI Has ReDoS via Unvalidated User-Controlled Regex in MCPToolIndex.search_tools()
CVE-2026-34726Medium· 4.4Copier `_subdirectory` allows template root escape via parent-directory traversal
Copier `_subdirectory` allows template root escape via parent-directory traversal
CVE-2026-34222High· 7.7Open WebUI has Broken Access Control in Tool Valves
Open WebUI has Broken Access Control in Tool Valves
CVE-2026-34520Critical· 9.1AIOHTTP's C parser (llhttp) accepts null bytes and control characters in response header values - header injection/security bypass
AIOHTTP's C parser (llhttp) accepts null bytes and control characters in response header values - header injection/security bypass
CVE-2026-34445High· 8.6ONNX: Malicious ONNX models can crash servers by exploiting unprotected object settings.
ONNX: Malicious ONNX models can crash servers by exploiting unprotected object settings.
CVE-2026-34954High· 8.6PraisonAI Has SSRF in FileTools.download_file() via Unvalidated URL
PraisonAI Has SSRF in FileTools.download_file() via Unvalidated URL
CVE-2026-34517LowAIOHTTP has late size enforcement for non-file multipart fields causes memory DoS
AIOHTTP has late size enforcement for non-file multipart fields causes memory DoS
CVE-2026-34514LowAIOHTTP has CRLF injection through multipart part content type header construction
AIOHTTP has CRLF injection through multipart part content type header construction
CVE-2026-34591Medium· 6.5Poetry Has Wheel Path Traversal Which Can Lead to Arbitrary File Write
Poetry Has Wheel Path Traversal Which Can Lead to Arbitrary File Write
CVE-2026-74874Mediumopenssl-encrypt has non-cryptographic PRNG used for steganography pixel selection
openssl-encrypt has non-cryptographic PRNG used for steganography pixel selection
CVE-2026-74872Mediumopenssl-encrypt: Dynamic .so loading for Whirlpool uses broad glob pattern without integrity verification
openssl-encrypt: Dynamic .so loading for Whirlpool uses broad glob pattern without integrity verification
CVE-2026-74878Criticalopenssl-encrypt: TOTP rate limiter is in-memory only — not shared across workers, lost on restart
openssl-encrypt: TOTP rate limiter is in-memory only — not shared across workers, lost on restart
CVE-2026-74873Mediumopenssl-encrypt has visible password in process list via --password CLI argument
openssl-encrypt has visible password in process list via --password CLI argument
CVE-2026-74875Mediumopenssl-encrypt silently skips schema validation when jsonschema library is not installed
openssl-encrypt silently skips schema validation when jsonschema library is not installed
CVE-2026-34203Low· 2.7Nautobot: Management of users via REST API does not apply configured password validators
Nautobot: Management of users via REST API does not apply configured password validators
CVE-2026-32794Medium· 4.8PoCApache Airflow Provider for Databricks: TLS Certificate Verification is Disabled in Databricks Provider K8s Token Exchange
Apache Airflow Provider for Databricks: TLS Certificate Verification is Disabled in Databricks Provider K8s Token Exchange
CVE-2026-32716High· 8.1SciTokens has an Authorization Bypass via Incorrect Scope Path Prefix Checking
SciTokens has an Authorization Bypass via Incorrect Scope Path Prefix Checking
CVE-2026-27124HighFastMCP: Missing Consent Verification in OAuth Proxy Callback Facilitates Confused Deputy Vulnerabilities
FastMCP: Missing Consent Verification in OAuth Proxy Callback Facilitates Confused Deputy Vulnerabilities
CVE-2026-34531Medium· 6.5Flask-HTTPAuth invokes token verification callback when missing or empty token was given by client
Flask-HTTPAuth invokes token verification callback when missing or empty token was given by client
CVE-2026-34881Medium· 5.0OpenStack Glance is affected by Server-Side Request Forgery (SSRF)
OpenStack Glance is affected by Server-Side Request Forgery (SSRF)
CVE-2025-64340Medium· 6.7FastMCP has a Command Injection vulnerability - Gemini CLI
FastMCP has a Command Injection vulnerability - Gemini CLI